GHSA-fq3w-p4fg-mw73Low▾ Sunlitfixurjavainstall: Previous Fuji versions can accidentally wipe `/usr/share/man/man8`
▾ Sunlit zone — Low / medium · no exploitation signal
impact 13.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Affects: Anyone who generates the UNIX man pages in Fuji <= 0.8.0 build with the dev crate feature.
Consequences: /usr/share/man/man8 may be entirely removed & re-created without any of the previous entries.
At the time of writing, no new version has been released on crates.io, due to an unrelated CI/CD publishing issue. Due to the same unrelated publishing issue, no new GitHub Releases version has been released.
Do not run fuji manual on non-dev builds for versions <= 0.8.0.
This bug results from development-only code being accidentally left in for release use.
Previous versions of Fuji are still "safe" to use, provided that you do not run fuji manual.
There is no malicious potential from this, it's just a major annoyance to accidentally remove all your sysadmin man pages.
fixurjavainstall <= 0.8.0Upgrade to a patched release:
fixurjavainstall 0.8.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-81943Medium· 6.7PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain active debug functionality in the embedded software
CVE-2026-53952Critical· 9.8GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS
CVE-2026-6485High· 8.2UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.
CVE-2026-58191Medium· 6.5Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes
CVE-2026-41186High· 7.5When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authentication
CVE-2025-4106NoneAn authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover dia…